CVE-2020-15217: GLPI-Project GLPI
Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.
In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in 9.5.2. As a workaround, disable public access to the FAQ.
Affected products
- GLPI-Project GLPI: from 9.5.0, before 9.5.2 (fixed in 9.5.2)
Published 2020-10-07. Last modified 2026-06-17.